CVE-2020-6994| ºÕ˹ÂüHiOSºÍHiSecOS²úÆ·°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-01

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-6994

ʱ    ¼ä

2020-04-01

Àà    ÐÍ

»º³åÇøÒç³ö

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

HiOS <= 07.0.02 Ó°Ïì²úÆ·£ºRSP£¬£¬£¬ £¬ £¬£¬RSPE£¬£¬£¬ £¬ £¬£¬RSPS£¬£¬£¬ £¬ £¬£¬RSPL£¬£¬£¬ £¬ £¬£¬MSP£¬£¬£¬ £¬ £¬£¬EES£¬£¬£¬ £¬ £¬£¬ EESX£¬£¬£¬ £¬ £¬£¬GRS£¬£¬£¬ £¬ £¬£¬OS£¬£¬£¬ £¬ £¬£¬RED»¥»»»ú£»£»£»£»£»£»£»

HiSecOS0 <= 3.2.00 Ó°Ïì²úÆ·£ºEAGLE 20/30·À»ðǽ

x01 ·ì϶ÏêÇé


µÂ¹úºÕ˹Âü×Ô¶¯»¯ºÍ½ÚÔ칫˾µÞÔìÓÚ1924Ä꣬£¬£¬ £¬ £¬£¬ÒµÎñÉ¢²¼ÔÚ×Ô¶¯»¯Í¨Ñ¶ÁìÓò£¬£¬£¬ £¬ £¬£¬²úÆ·ÁìÓòÔ̺¬Ñ¡È¡Ä£ÄâºÍÊý×ֹ㲥µçÊÓ´«Êä¼¼ÊõµÄÒÆ¶¯·¢ÉäºÍ½Ó¹Üϵͳ£¬£¬£¬ £¬ £¬£¬ÆóÒµºÍ¹¤ÒµÍøÂç½â¾ö¹æ»®ÒÔ¼°ÏÖ³¡×ÜÏßϵͳ¡£¡£¡£ ¡£¡£¡£¡£ºÕ˹ÂüÔÚ2007Äê±»ÃÀ¹ú°Ùͨ£¨Belden£©¹«Ë¾ÊÕ¹º¡£¡£¡£ ¡£¡£¡£¡£ºÕ˹ÂüHiOSºÍHiSecOS¶¼ÊǰÙÍ¨ÍÆ³öµÄ°²È«²Ù×÷ϵͳ¡£¡£¡£ ¡£¡£¡£¡£


HiOSºÍHiSecOSµÄHTTP(S)web serverÖдæÔÚÒ»¸ö»º³åÇøÒç¶Âí½Å¡£¡£¡£ ¡£¡£¡£¡£¸Ã·ì϶ԴÓÚ¶ÔURL²ÎÊýµÄ½âÎö²»µ±ÒýÆðµÄ¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßÄܹ»½èÖúÌØÔìµÄHTTPÒªÇóÈëÇÖÖ¸±êÉ豸£¬£¬£¬ £¬ £¬£¬Ôì³ÉÄÚ²¿»º³åÇøÒç³ö¡£¡£¡£ ¡£¡£¡£¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѽ¨¸´¸Ã·ì϶£¬£¬£¬ £¬ £¬£¬½¨ÒéHiOSÓû§¾¡¿ì¸üÐÂÖÁ07.0.03»ò¸ü¸ß°æ±¾£¬£¬£¬ £¬ £¬£¬HiSecOSÓû§¸üÐÂÖÁ03.3.00»ò¸ü¸ß°æ±¾¡£¡£¡£ ¡£¡£¡£¡£

һʱ´ëÊ©¿ÉʹÓá°IP½Ó¼ûÏÞ¶È¡±Ö°ÄÜ£¬£¬£¬ £¬ £¬£¬ÏÞ¶ÈHTTPºÍHTTPS¶Ô¿ÉÐÅIPµØÖ·µÄ½Ó¼û£¬£¬£¬ £¬ £¬£¬»òÕß½ûÓÃHTTPºÍHTTPS·þÎñÆ÷¡£¡£¡£ ¡£¡£¡£¡£


https://www.belden.com/hubfs/support/security/bulletins/Belden_Security_Bulletin_BSECV-2020-01_1v2_FINAL.pdf?hsLang=en


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-091-01


0x05 ¹¦·òÏß


2020-02-14 °ä²¼·ì϶

2020-02-26 ÍÆ³ö½â¾ö¹æ»®

2020-03-24 »ñµÃCVE±àºÅ